PT-2025-7124 · Webkul · Webkul Qloapps

·

CVE-2025-26058

·

Published

2025-02-18

·

Updated

2025-02-19

CVSS v3.1

4.2

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Webkul QloApps version 1.6.1
Description: The issue exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
Recommendations: For Webkul QloApps version 1.6.1, consider modifying the application to prevent appending authentication tokens to URLs during redirection, or implement an alternative secure method for handling user authentication. As a temporary workaround, restrict access to the admin panel and other protected areas to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26058

Affected Products

Webkul Qloapps